Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-774q-wfcp-vc2q

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Moodle Email media URL tokens were not checking for user status

A vulnerability was found in Moodle 3.6 before 3.6.7 and 3.7 before 3.7.3, where tokens used to fetch inline atachments in email notifications were not disabled when a user's account was no longer active. Note: to access files, a user would need to know the file path, and their token.

Пакеты

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.6, < 3.6.7

3.6.7

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.7, < 3.7.3

3.7.3

EPSS

Процентиль: 52%
0.00289
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-285
CWE-862

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 5 лет назад

A vulnerability was found in Moodle 3.6 before 3.6.7 and 3.7 before 3.7.3, where tokens used to fetch inline atachments in email notifications were not disabled when a user's account was no longer active. Note: to access files, a user would need to know the file path, and their token.

CVSS3: 5.3
nvd
больше 5 лет назад

A vulnerability was found in Moodle 3.6 before 3.6.7 and 3.7 before 3.7.3, where tokens used to fetch inline atachments in email notifications were not disabled when a user's account was no longer active. Note: to access files, a user would need to know the file path, and their token.

CVSS3: 5.3
debian
больше 5 лет назад

A vulnerability was found in Moodle 3.6 before 3.6.7 and 3.7 before 3. ...

EPSS

Процентиль: 52%
0.00289
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-285
CWE-862